heyeddi-pr-respond

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow is coherent for PR response automation, but it is high-risk because it enables autonomous code changes, commits, pushes, and public replies without confirmation, and it depends on several unverifiable helper commands whose provenance is not documented in the skill. Data flow to GitHub is proportionate, so this is not confirmed malware, but the execution trust and autonomy footprint are too broad to treat as benign.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Sep 11, 2026, 03:39 AM
Package URL
pkg:socket/skills-sh/heyeddi-com%2Fheyeddi-skills%2Fheyeddi-pr-respond%2F@4e511b97ad95339792b22dca61bbf01aade9a7a5c49f8b672aae97953795cfbf
Security Audit — socket — heyeddi-pr-respond